[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
NFS security
- To: silug-discuss@silug.org
- Subject: NFS security
- From: "Ken Keefe" <kjkeefe@gmail.com>
- Date: Fri, 19 Dec 2008 13:08:59 -0600
- DKIM-Signature: v=1; a=rsa-sha256; c=relaxed/relaxed; d=gmail.com; s=gamma; h=domainkey-signature:received:received:message-id:date:from:to :subject:mime-version:content-type; bh=Ipgo/V2hMSyUDuWap5W7hDJBG7VjJdr0yND8S0qmzaE=; b=HeHqbpS/mNlARPJUm2ZCR5vzvsOMiHFli1IfC2KrHiRNoRRiPjPXwrTBYOoyfarmGq Ieqk90vL3fYBMypGZ9nW1IC7Nc6pld6hNYiCapsNsu956E/GHgJmcUPvesxUY5u96S0H HDMNECdAtRffT5fKsPQIrFRSF0Tl8SkHBonBA=
- DomainKey-Signature: a=rsa-sha1; c=nofws; d=gmail.com; s=gamma; h=message-id:date:from:to:subject:mime-version:content-type; b=mAerKvzE2iBgrPAUo4/JVQmEiFh0TImcFPs3lSf/imBgUoiJrum9RmTdo20cHI6GRG 8BHUE9zPitkJL2Skgq/1onLwFnFV7AVMcKy42R2b9DQdNjHI+52Q3McZDTYquyvpf4yh QaKXXloyUxjf+ZT9da724rn7Yf1Er529gxizo=
- Organization: Southern Illinois Linux Users Group
- Reply-To: silug-discuss@silug.org
- Sender: silug-discuss-owner@silug.org
Hello all. I just recently set up my first NFS share between several PC's. I'd read about it, seen it in action, but never done it myself. The setup I did was a very vanilla (I think) configuration. However, I was wondering about how systems like this are secured. It seems to me that the only protection in place is that NFS limits the various exports by IP address. However, this could easily be circumvented by someone sniffing packets on a network and then setting their IP to one of the permitted IP's in order to gain access. This also seems pretty dangerous given how file ownership is managed across NFS shares. It is not hard to imagine how a would-be attacker could become root on their local machine and copy some files over to the server that allowed them to later become root on that server.
So, I've probably hashed over a bunch of stuff you already knew. My questions are: How do you accomplish filesystem sharing in a homogenous linux environment? If you use NFS, how can you secure it from the weaknesses I mentioned?
Any advice you have would be most appreciated as I have been tasked with building a little workgroup of linux machines that share disk space on a linux server and I want to do the right thing security-wise.
Thanks!
Ken
--
Forti et Fideli nihil difficile – Nothing is difficult to the brave and faithful.